Fix cross user package visibility leakage for hasSigningCertificate

- To fix cross user package visibility leakage for the API
  #hasSigningCertificate, this CL returns false if the target
  package does not install in the calling user.

Bug: 229684723
Test: atest CrossUserPackageVisibilityTests
Change-Id: Id82ed5d2d4678acf185ea3561787c0213d4c0224
This commit is contained in:
Rhed Jao
2022-05-31 19:40:57 +08:00
parent d7a58241b6
commit 6e8d0f67ad

View File

@@ -4453,13 +4453,11 @@ public class ComputerEngine implements Computer {
if (p == null) {
return false;
}
final PackageStateInternal ps = getPackageStateInternal(p.getPackageName());
if (ps == null) {
return false;
}
final int callingUid = Binder.getCallingUid();
final int callingUserId = UserHandle.getUserId(callingUid);
if (shouldFilterApplication(ps, callingUid, callingUserId)) {
final PackageStateInternal ps = getPackageStateInternal(p.getPackageName());
if (ps == null
|| shouldFilterApplicationIncludingUninstalled(ps, callingUid, callingUserId)) {
return false;
}
switch (type) {